← Vulnerability feed

Vulnerability record · CVE-2021-35587 · published 19 January 2022

CVE-2021-35587: Oracle Access Manager OpenSSO Agent missing authentication allows takeover

Oracle · Access Manager

Oracle Access Manager (Fusion Middleware) contains a missing-authentication flaw in the OpenSSO Agent component affecting versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it over HTTP to fully compromise the product. Because it is remotely reachable without credentials and rated 9.8, it is a high-value target for initial access.

9.8 CVSS 3.1 Critical CISA KEV since 28 Nov 2022 EPSS 96% · top 0.1% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network takeover, KEV-listed with known exploitation, and EPSS above 96 percent make this an urgent patch.

What it is

Oracle Access Manager (Fusion Middleware) contains a missing-authentication flaw in the OpenSSO Agent component affecting versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it over HTTP to fully compromise the product. Because it is remotely reachable without credentials and rated 9.8, it is a high-value target for initial access.

Impact

Successful exploitation results in complete takeover of Oracle Access Manager, with high confidentiality, integrity and availability impact. An attacker gains control of the affected service and any identity data or sessions it brokers.

Attack surface

Reached over the network via HTTP against the OpenSSO Agent component; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed Access Manager instance is in scope.

Exploitation

Listed in CISA KEV since 2022-11-28 with a required remediation date of 2022-12-19, indicating known exploitation in the wild. EPSS is 0.96284 (99.877th percentile), so exploitation is highly likely; no ransomware campaign use is documented.

What to do

  • Apply the Oracle January 2022 Critical Patch Update (cpujan2022) for Access Manager 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0.
  • If patching cannot be immediate, remove direct network exposure of the OpenSSO Agent/HTTP interface and restrict access to trusted networks.
  • Place affected instances behind an authenticating reverse proxy or WAF and block unauthenticated requests to the agent endpoints.
  • Rotate credentials and invalidate sessions on any instance that may have been exposed, and review for unauthorized configuration changes.
  • Confirm remediation against the CISA KEV due date and track the instance until the patch is verified.

Detection

  • Review Access Manager and OpenSSO Agent HTTP logs for unauthenticated requests to agent endpoints, especially anomalous or unexpected paths.
  • Hunt for post-exploitation signs: new or modified admin accounts, unexpected configuration changes, and outbound connections from the Access Manager host.
  • Monitor for exploitation attempts against exposed Access Manager interfaces using network or WAF signatures and alert on repeated unauthenticated access.
  • Correlate host and application logs around the KEV window for indicators of service takeover or session manipulation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-35587 to the Known Exploited Vulnerabilities catalog on 28 November 2022 as "Oracle Fusion Middleware Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 December 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35587 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed10.0CVE-2026-71133Oracle access manager improper authentication vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.51%10.0CVE-2026-60358Oracle access manager improper access control vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.51%9.9CVE-2026-73945Oracle access manager improper access control vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.43%9.9CVE-2026-71163Oracle access manager improper access control vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.39%9.9CVE-2026-60333Oracle access manager improper authentication vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.43%9.9CVE-2026-35313Oracle access manager improper access control vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.43%9.8CVE-2026-73950Oracle access manager improper authentication vulnerabilityVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affect…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2021-35587), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.